List secretsList the secrets in the connection's region with their metadata - never their values. The list can lag a few minutes behind changes.
Describe secretRead a secret's metadata - description, tags, versions and their labels, rotation, replicas and deletion date - without its value.
Get secret valueRead a secret's value - the current version unless a version id or label is given. A JSON value is also returned parsed as secret_json, so a later step can use secret_json.password.
Get several secret valuesRead up to 20 secrets' values in one step, either named in a list or chosen by a filter (not both). Secrets that could not be read are listed in errors.
Create secretCreate a secret, with its first value. AWS bills $0.40 per secret per month (prorated) from creation.
Update secretChange a secret's description, KMS key and/or value. A new value becomes the current version and the old one is kept as AWSPREVIOUS. Avoid storing new values more often than every 10 minutes - a secret holds at most 100 versions.
Put secret valueStore a new value as a new version. It becomes AWSCURRENT unless labels are given. Avoid storing new values more often than every 10 minutes - a secret holds at most 100 versions.
Delete secretSchedule a secret for deletion after a recovery window (7-30 days, default 30), during which Restore secret brings it back - or delete it immediately. A secret with replicas must have them removed first.
Restore secretCancel a secret's scheduled deletion.
List secret versionsList a secret's versions and their labels (no values), plus the id of the current one.
Move secret version labelMove a label such as AWSCURRENT from one version to another - this is how a secret is rolled back. When the label is already on a version, give that version as 'Remove from version'. Moving AWSCURRENT also moves AWSPREVIOUS.
Tag secretAdd tags to a secret, overwriting the value of any key it already has.
Remove secret tagsRemove tags from a secret by key.
Generate random passwordGenerate a random password to store in a secret. Nothing is saved by this step.
Get resource policyRead the resource policy attached to a secret, if it has one.
Set resource policyAttach a resource policy to a secret, replacing any existing one. Policies that would make the secret public are blocked unless you turn that off.
Delete resource policyRemove the resource policy from a secret.
Validate resource policyCheck a resource policy for errors and public access without saving it. Needs both the ValidateResourcePolicy and PutResourcePolicy permissions.
Replicate secret to regionsCopy a secret into other regions and keep them in sync. Each replica is billed as a secret. Replication finishes in the background - check replication_status with Describe secret.
Remove replica regionsStop replicating a secret to regions and delete those replicas.